MALICIOUS — 82709534989.pdf
MALICIOUS — 82709534989.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100). 4 of 50 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
d10df20c5b494aed7d51ba6aca8c5aa3e47af04e60523199b668eeb4707f2a8a - SHA-1:
c651e25a0f967b26ee3444058aa708a6f74a347c - MD5:
49275eada3319b1c0fc17a18fa377eef - ssdeep:
1536:u/K+qjebRHfAgktdlMAhymoAmUwbsvK2w1suSl1AfW4Jg2yDbQ6WApO6zPGU:YTqjebEtdWtmoAmUNv638AtJg2Bx69 - TLSH:
T17C38CFF3105BED4D778B9F43B9F711A8B18A978C2126ABA08088B67C887C57DBF04551 - Submitted as: 82709534989.pdf
- File type: pdf · Size: 82509 bytes
- Verdict: malicious (100/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (Lazarus): root_.cache_dconf_user - dynamic signal, weight 0.80, confidence 0.90
- Embedded link rated malicious by URL analysis: https://dycmc.com/DATA/upload/files/202106192304547446.pdf - network signal, weight 0.70, confidence 0.80
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Contacted 39 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://pistant.ru/uplcv?utm_term=owners+manual+2014+ford+focus+se, https://dycmc.com/DATA/upload/files/202106192304547446.pdf, https://www.pharmaright.ca/wp-content/plugins/super-forms/uploads/php/files/3j8ep6s4bofl54bs86pb85ob97/28203878668.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9662 behavior events · 1 ATT&CK techniques · 4 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- desktop-hsgcbep
- _http._tcp.archive.ubuntu.com
- archive.ubuntu.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 250.255.255.239.in-addr.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- http://www.msftconnecttest.com/connecttest.txt
Dropped files
- /opt/CAPEv2/storage/analyses/30398/files/f68f6fa558210db192353ead45acfb0725fd7d2f02c2498b77f37f94a5c8e0dc -
f68f6fa558210db192353ead45acfb0725fd7d2f02c2498b77f37f94a5c8e0dc - /opt/CAPEv2/storage/analyses/30398/files/e47d30b0f75f4d023e1406e89803cb06ff3aa340a173cf6bd80a19c96de38e2e -
e47d30b0f75f4d023e1406e89803cb06ff3aa340a173cf6bd80a19c96de38e2e - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 - tmp_tmp.XCHa1L09dh -
11bc29985b0550fe5a6110823a23299cf789d389fcc0db66c6e9aa488e3b2fbf
Embedded URLs
- https://pistant.ru/uplcv?utm_term=owners+manual+2014+ford+focus+se
- https://dycmc.com/DATA/upload/files/202106192304547446.pdf
- https://www.pharmaright.ca/wp-content/plugins/super-forms/uploads/php/files/3j8ep6s4bofl54bs86pb85ob97/28203878668.pdf
- https://sindicav.com.br/ckeditor/ckfinder/userfiles/files/94393931569.pdf
- https://afmiletisim.com/resimler/files/43856135988.pdf
- https://olgapopovaphoto.com/wp-content/plugins/super-forms/uploads/php/files/2afe88c1bb30667106eeac2a98d4629b/88363240149.pdf
- https://alcc.vn/wp-content/plugins/super-forms/uploads/php/files/jvaqp3svso0v2ru9nh243m1um2/88470822596.pdf
- https://maxim-catering.de/wp-content/plugins/super-forms/uploads/php/files/7h3o84fdqg89frrkhcscugfj6g/wupidovapujamefana.pdf
- http://pansophers.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609a96ec5818b---bodanokopa.pdf
- https://diversifiedhumansolutions.com/wp-content/plugins/super-forms/uploads/php/files/d5773aabf849ee702a7dce08a4db7782/46867379602.pdf
- http://www.davidwoodpersonnel.com/wp-content/plugins/formcraft/file-upload/server/content/files/160e02bba80513---buzufi.pdf
- https://mudateconmigo.cl/wp-content/plugins/super-forms/uploads/php/files/af6f8e557c264eed59216312526d24ba/24575829966.pdf
- http://apsons.eu/files/file/safidoxemanujezetepitege.pdf
- https://polinagerz.ru/wp-content/plugins/super-forms/uploads/php/files/pigvopscr2vvl57ca3kd7l9nen/vesotokusevul.pdf
- http://fabiocaronearchitetto.com/userfiles/files/92794143682.pdf
- https://projectmine.hu/ckfinder/userfiles/files/21892271128.pdf
- https://acethamessecurity.co.uk/wp-content/plugins/super-forms/uploads/php/files/fd142edf07590add65f9c23ee8b67015/95968315754.pdf
- https://www.mobytec.com.br/mobytec/wp-content/plugins/formcraft/file-upload/server/content/files/160c94e5069ea8---87807503936.pdf
- https://www.caissedesecolesdu5eme.fr/backoffice/ckfinder/userfiles/files/79078711018.pdf
- http://ssteelelaw.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/beguneku.pdf
- https://grand-forge.ru/wp-content/plugins/super-forms/uploads/php/files/4470a7279e9fefa591693d4c90e84ffb/73263081621.pdf
- http://kolaykanal.com/userfiles/files/52358603890.pdf
- http://www.chp.pl/ckfinder/userfiles/files/20093740663.pdf
- http://mptech.vn/ckfinder/userfiles/files/25189303248.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- pistant.ru
- dycmc.com
- www.pharmaright.ca
- sindicav.com.br
- afmiletisim.com
- olgapopovaphoto.com
- maxim-catering.de
- pansophers.com
- diversifiedhumansolutions.com
- www.davidwoodpersonnel.com
- apsons.eu
- polinagerz.ru
- fabiocaronearchitetto.com
- acethamessecurity.co.uk
- www.mobytec.com.br
- www.caissedesecolesdu5eme.fr
- ssteelelaw.com
- grand-forge.ru
- kolaykanal.com
- www.chp.pl
- www.w3.org
- purl.org
- ns.adobe.com
- alcc.vn
- mudateconmigo.cl
Embedded IP addresses
- 138.201.132.148
- 4.150.223.104
- 74.178.240.61
- 74.178.76.44
- 4.150.223.96
- 172.66.2.5
- 52.110.12.50
- 52.110.12.55
- 4.230.171.124
- 57.155.101.212
- 203.26.79.13
- 135.232.92.137
- 74.178.240.51
- 52.123.129.14
- 52.123.252.203
- 40.99.134.2
- 52.123.252.198
- 135.233.95.80
- 92.223.78.30
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report